Ledger Fixes Vulnerability in Ethereum App
Ledger, a digital wallet company, has issued a statement regarding a vulnerability in its Ethereum app. Researchers from rival wallet maker OneKey were able to reproduce the issue using an older version of the app, 1.22.1.
The flaw could have allowed an attacker to replace transaction details before a user signed them, potentially leading to unauthorized transactions.
Ledger's Chief Technology Officer Charles Guillemet stated that the issue had already been fixed in version 1.22.2, released on August 13.
Ledger emphasizes that an attacker would need control over communications between the device and host through malware or a compromised wallet app, and there is no evidence of attacks in the wild.